Real-Time Events data sources
Look up each Real-Time Events data source, the product that writes its records, the GraphQL dataset that holds them, and how long they are kept.
A data source is the Azion product or service that produced the events you query. On a query it is the index the records are read from, so selecting a data source is mandatory. Real-Time Events exposes eight of them, and each one carries its own set of preorganized variables, because each product writes a different record.
The same records are reached two ways: through Azion Console and through the Real-Time Events GraphQL API. This page carries the variable names the classic view of Azion Console shows, which is the view Real-Time Events opens on. The GraphQL API holds each data source as a dataset and names its fields in camelCase, so the variable Remote Address below is the field remoteAddress there. A Data Stream payload writes that same field in snake_case again. The Filter by field takes a third form of the same name: the variable in lowercase, with underscores, so a search on Geoloc Country Name reads geoloc_country_name='Germany'. For the syntax and a worked set, refer to Filter events. Each section below names its dataset and links the field list. To send a first query, refer to GraphQL API first steps.
HTTP Requests
HTTP Requests carries one record per request that reaches an application or a firewall. The record holds the request line, the response status, the cache status, and the Web Application Firewall (WAF) fields of that request.
These records require an application, a firewall, and WAF.
In the GraphQL API the same records are the workloadEvents dataset, named httpEvents before. For its fields, refer to workloadEvents.
| Variable | Description |
|---|---|
| Bytes Sent | Number of bytes sent to a client. This field is the result of a sum. Example: 191 |
| Debug Log | Value of any variable from the request, set through a Rules Engine behavior. Example: {"idHash":"pQ04xXYD4JSYyOERu3mcwA==","type":"product_screen_element_element_action","message":{"event":"product_screen_element_element_action","action":"value","product":"value","screen":"value","element":"value"},"date":"2023-10-27T19:44:57.251Z"} |
| Geoloc ASN | Autonomous System Number (ASN) Allocation queried from the MaxMind table. Example: AS52580 Azion Technologies Ltda. |
| Geoloc Country Name | Remote client’s country detected via IP address geolocation. Example: United States, Germany |
| Geoloc Region Name | Remote client’s region detected via IP address geolocation. Example: California, Bavaria |
| Host | Host information sent on the request line. Stores: host name from the request line, or host name from the Host request header field, or the server name matching a request. Example: xxxxxxxxxx.map.azionedge.net |
| HTTP Referer | Address of the page the user made the request from. Example: https://example.com |
| HTTP User Agent | End user’s application, operating system, vendor, and version. Value of the User-Agent header. Example: Mozilla/5.0 (Windows NT 10.0; Win64; x64) |
| Proxy Status | HTTP error status code or origin when no response is obtained from the upstream. Example: 520. In case of cache, the response is -. |
| Request Length | Request length in bytes, including request line, headers, and body. This field is the result of a sum. Example: 167 |
| Request Method | HTTP request method. Example: GET or POST |
| Request Time | Request processing time, in seconds, since the first bytes were read from the client. This field is the result of a sum. Example: 0.234 |
| Request Uri | URI of the request made by the end user, without the host and protocol information and with arguments. Example: /v1?v=bo%20dim |
| Remote Address | IP address of the origin that generated the request. Example: 127.0.0.1 |
| Remote Port | Port of the origin that generated the request. Example: 8080 |
| Scheme | Request scheme. Example: HTTP or HTTPS |
| Server Protocol | Version of the request protocol. Example: HTTP/1.1, HTTP/2.0, HTTP/3.0 |
| Sent HTTP Content Type | Content-Type header sent in the origin’s response. Example: text/html; charset=UTF-8 |
| SSL Cipher | Cipher string used to establish TLS connection. Example: TLS_AES_256_GCM_SHA384 |
| SSL Protocol | Protocol for an established TLS connection. Example: TLS v1.2 |
| Stack Trace | Provides the names of the Rules Engine from your application or your firewall that are run by the request. Example: {\\\"edge_firewall\\\":[\\\"Global - Set WAF\\\"]} |
| Status | HTTP status code of the request. Example: 200 |
| Upstream Addr | Client’s IP address and port. Can also store multiple servers or server groups. Example: 192.168.1.1:80. When the response is 127.0.0.1:1666, the upstream is Azion Runtime. |
| Upstream Bytes Received | Number of bytes received from the origin when the content is not cached. Example: 8304 |
| Upstream Bytes Sent | Number of bytes sent to the origin. Example: 2733 |
| Upstream Cache Status | Status of the local cache. Can be: MISS, BYPASS, EXPIRED, STALE, UPDATING, REVALIDATED, HIT, or - |
| Upstream Response Time | Time taken to receive a default response from the origin in seconds, including headers and body. Example: 0.876. In case of cache, the response is - |
| Upstream Status | HTTP status code of the origin. If a server cannot be selected, the variable keeps the 502 (Bad Gateway) status code. Example: 200. In case of cache, the response is 0 |
| Waf Block | Informs whether WAF blocked the action or not. 0 when action was not blocked; 1 when action was blocked. When in Learning Mode, it is not blocked regardless of the return. |
| Waf Ev Headers | When the request headers sent by the user are analyzed by WAF and tagged as blocked with $waf_block = 1, it contains a base64 encoded string. Otherwise, it contains a dash character -. It applies to both WAF Learning or Blocking modes. |
| Waf Learning | Informs if WAF is in Learning mode. Returns 0 if it is not and 1 if it is. |
| Waf Match | List of infractions found in the end user’s request. It is formed by key-value elements: the key refers to the type of violation detected; the value shows the string that generated the infraction. Example: 0:1402:HEADERS:cookie |
| Waf Score | Reports the score that will be increased in case of a match with the rules set for the WAF. Can be SQL, XSS, TRAVERSAL or RFI. |
| Waf Total Blocked | Total number of blocked requests. Example: 2 |
| Waf Total Processed | Total number of processed requests. Example: 5 |
The Stack Trace variable is filled only where the Debug Rules feature is turned on in the application. For how to turn it on and read what it writes, refer to Debug rules created with Rules Engine.
The Set WAF [Your WAF] behavior on a firewall performs special processing and lets other rules run at the same time. The Stack Trace variable therefore lists those other rules even where the WAF rule set is set to block and return the request. The WAF rules still block the requests that match their criteria, and this is standard platform behavior.
Functions
Functions carries one record per request that invokes a function. The record holds the function instances the request ran, the order it ran them in, and the time they took.
These records require Functions.
In the GraphQL API the same records are the functionEvents dataset, named edgeFunctionsEvents before. For its fields, refer to functionEvents.
For the other ways to read what a function wrote, refer to Troubleshoot Functions.
| Variable | Description |
|---|---|
| Configuration ID | Unique Azion configuration identifier set on virtual host configuration file. Example: 1595368520 |
| Functions Instance ID List | List of Functions instances that were invoked during the request. Example: 10728 |
| Functions Initiator Type List | List of initiators used in the function separated by ;. Can be 1 (Application) or 2 (Firewall). |
| Functions List | List of Functions that were invocated during the request, in order. The order begins from left to right, meaning functions on the left were invocated first. Example: 3324;43 |
| Functions Solution ID | Identifier of your function. Example: 1321 |
| Functions Time | Total execution time, in seconds, for the function during its processing. This field is the result of a sum. Example: 0.021 |
| Function Language | Language used in the function. Example: javascript |
| Virtual Host ID | Unique ID available on Azion Console. Set on virtual host configuration file. Example: 2410001a |
Functions Console
Functions Console carries the log lines a function writes to the console while it runs on Azion Runtime. One request produces several lines, and the ID variable groups the lines of a single request.
In the GraphQL API the same records are the functionConsoleEvents dataset, named cellsConsoleEvents before. For its fields, refer to functionConsoleEvents.
| Variable | Description |
|---|---|
| Configuration ID | Unique Azion configuration identifier set on virtual host configuration file. Example: 1595368520 |
| Function ID | Unique Azion function identifier number. Can be found on Azion Console’s function URL path or via API request. Example: 1111 |
| ID | Request identifier. Aggregates multiple messages from a single request. Example: 240g95f04832f2872dd6e8ae308e8a73 |
| Level | Message with the level type for the function. Can be MDN, DEBUG, INFO, ERROR, LOG, or WARN |
| Line | Log message generated by Azion Runtime. Example: at async mainFetch (ext:deno_fetch/26_fetch.js:266:12) |
| Line Source | Log message category. Example: CONSOLE, RUNTIME |
| Solution ID | Unique Azion ID set on virtual host configuration file for the solution. Example: 1441740010 |
Image Processor
Image Processor carries one record per request an application serves through Image Processor. The record holds the request, the TLS parameters of the connection, and the cache status of the processed image.
These records require Image Processor.
In the GraphQL API the same records are the imageProcessedEvents dataset, which carries no previous name. For its fields, refer to imageProcessedEvents.
| Variable | Description |
|---|---|
| Bytes Sent | Number of bytes sent to a client. This field is the result of a sum. Example: 191 |
| Configuration ID | Unique Azion configuration identifier set on virtual host configuration file. Example: 1595368520 |
| Host | Host information sent on the request line. Stores: host name from the request line, or host name from the Host request header field, or the server name matching a request. Example: xxxxxxxxxx.map.azionedge.net |
| HTTP Referer | Address of the page the user made the request from. Example: https://example.com |
| HTTP User Agent | End user’s application, operating system, vendor, and version. Value of the User-Agent header. Example: Mozilla/5.0 (Windows NT 10.0; Win64; x64) |
| Reference Error | Reference ID of the request. Generated when the status code is bigger than 400. Example: #AECFE66100000000C947B9B3B3BFBE46FFFFFFFF9401 |
| Remote Addr | IP address of the origin that generated the request. Example: 127.0.0.1 |
| Remote Port | Port of the origin that generated the request. Example: 8080 |
| Request Method | HTTP request method. Example: GET or POST |
| Request Time | Request processing time, in seconds, since the first bytes were read from the client. This field is the result of a sum. Example: 0.234 |
| Request Uri | URI of the request made by the end user, without the host and protocol information and with arguments. Example: /v1?v=bo%20dim |
| Scheme | Request scheme. Example: HTTP or HTTPS |
| Solution | Identifier of your application. Example: 1321 |
| Source | Server that generated the log line. Example: edg-fln-ggn001p |
| SSL Cipher | Cipher string used to establish TLS connection. Example: TLS_AES_256_GCM_SHA384 |
| SSL Protocol | Protocol for an established TLS connection. Example: TLS v1.2 |
| SSL Session Reused | Returns r if an SSL session was reused or . if it was not. |
| Status | HTTP status code of the request. Example: 200 |
| TCP Info RTT | Round-Trip Time (RTT) in microseconds measured for the user. Available on systems that support the TCP_INFO socket option. Example: 72052 |
| Upstream Cache Status | Status of the local cache. Can be: MISS, BYPASS, EXPIRED, STALE, UPDATING, REVALIDATED, HIT, or - |
| Upstream Response Time | Time taken to receive a default response from the origin in seconds, including headers and body. This field is the result of a sum. Example: 0.876. In case of cache, the response is - |
| Upstream Status | HTTP status code of the origin. If a server cannot be selected, the variable keeps the 502 (Bad Gateway) status code. Example: 200. In case of cache, the response is -. |
Tiered Cache
Tiered Cache carries one record per request an application serves with Tiered Cache turned on. The record holds the cache key, the TTL the object was stored under, and the timing of each stage of the call to the origin.
These records require Tiered Cache.
In the GraphQL API the same records are the tieredCacheEvents dataset, which carries no previous name. For its fields, refer to tieredCacheEvents.
| Variable | Description |
|---|---|
| Bytes Sent | Number of bytes sent to a client. This field is the result of a sum. Example: 191 |
| Cache Key | The stored object cache identification key for the content requested by a client. Example: /index.html |
| Cache TTL | Time, in seconds, the cached object is considered valid (not expired). After the time expiration, when a new request occurs, Tiered Cache queries the data on the origin (upstream). Example: 31536000 |
| Configuration ID | Unique Azion configuration identifier set on virtual host configuration file. Example: 1595368520 |
| Host | Host information sent on the request line. Stores: host name from the request line, or host name from the Host request header field, or the server name matching a request. Example: xxxxxxxxxx.map.azionedge.net |
| Proxy Host | Hostname being proxied. Example: storage.googleapis.com:443 |
| Proxy Status | HTTP error status code or origin when no response is obtained from the upstream. Example: 520. In case of cache, the response is -. |
| Proxy Upstream | Origin (upstream) address. In some cases, the Tiered Cache origin can be Image Processor (IMS) to process the image and then cache it. Example: ims_http |
| Reference Error | Reference ID of the request. Generated when the status code is 4xx or 5xx. Example: #AECFE66100000000C947B9B3B3BFBE46FFFFFFFF9401 |
| Remote Addr | IP address of the origin that generated the request. Example: 127.0.0.1 |
| Remote Port | Port of the origin that generated the request. Example: 8080 |
| Request Length | Request length, including request line, headers, and body. This field is the result of a sum. Example: 167 |
| Request Method | HTTP request method. Example: GET or POST |
| Request Time | Request processing time, in seconds, since the first bytes were read from the client. This field is the result of a sum. Example: 0.234 |
| Request Uri | URI of the request made by the end user, without the host and protocol information and with arguments. Example: /v1?v=bo%20dim |
| Scheme | Request scheme. Example: HTTP or HTTPS |
| Sent HTTP Content Type | Content-Type header sent in the origin’s response. Example: text/html; charset=UTF-8 |
| Server Protocol | Request protocol. Example: HTTP/1.1, HTTP/2.0, HTTP/3.0 |
| Solution | Identifier of your application. Example: 1321 |
| Status | HTTP status code of the request. Example: 200 |
| TCP info RTT | Round-Trip Time (RTT) in microseconds measured for the user. Available on systems that support the TCP_INFO socket option. Example: 72052 |
| Upstream Bytes Received | Number of bytes received from the origin when the content is not cached. Example: 8304 |
| Upstream Cache Status | Status of the local cache. Can be: MISS, BYPASS, EXPIRED, STALE, UPDATING, REVALIDATED, HIT, or - |
| Upstream Connect Time | Time taken to establish a connection with the origin, in seconds. In the case of TLS, it includes time spent on handshake. Example: 0.123. Returns 0 for KeepAlive and - for cache |
| Upstream Header Time | Time taken to receive the response header from the origin, in seconds. Example: 0.345. In case of cache, the response is - |
| Upstream Response Time | Time taken to receive a default response from the origin in seconds, including headers and body. Example: 0.876. In case of cache, the response is - |
| Upstream Status | HTTP status code of the origin. If a server cannot be selected, the variable keeps the 502 (Bad Gateway) status code. Example: 200. In case of cache, the response is -. |
Edge DNS
Edge DNS carries one record per query answered by Edge DNS. The record names the zone, the record type asked for, and the status the resolver returned.
These records require Edge DNS.
In the GraphQL API the same records are the edgeDnsQueriesEvents dataset, which carries no previous name. For its fields, refer to edgeDnsQueriesEvents.
| Variable | Description |
|---|---|
| Level | Level of the log generator: ERROR, WARN, INFO, DEBUG, or TRACE |
| Q Type | Definition of the type of record that will be used. Example: PTR, A, AAAA, HTTPS, NS, SRV |
| Resolution Type | Method types used to resolve hosts. Example: standard |
| Source | Server that generated the log line. Example: edg-fln-ggn001p |
| Status Code | HTTP status code of the request. Example: 200 |
| Solution ID | Identifier of your Edge DNS instance. Example: 1321 |
| UUID | Unique request identifier. Example: b204b8c3-e463-4c3d-af3d-025703a4 |
| Zone ID | Unique identifier of the Edge DNS zone. Example: 1340 |
Data Stream
Data Stream carries one record per delivery made to a configured endpoint. The record names the endpoint, the volume it carried, and the status the endpoint answered with. A destination that rejects a delivery is therefore visible in the same place as the traffic that fed it.
These records require Data Stream.
In the GraphQL API the same records are the dataStreamedEvents dataset, which carries no previous name. For its fields, refer to dataStreamedEvents.
| Variable | Description |
|---|---|
| Configuration ID | Unique Azion configuration identifier set on virtual host configuration file. Example: 1595368520 |
| Data Streamed | Total amount of data streamed, in bytes, to the configured endpoint. This field is the result of a sum. Example: 1270 |
| Endpoint Type | Type of endpoint used in the configured Data Stream. Can be: HTTP_POST, S3, ELASTICSEARCH, QRADAR, AWS_KINESIS_FIREHOSE, KAFKA, DATADOG, BIG_QUERY, SPLUNK, AZURE_MONITOR, AZURE_BLOB_STORAGE |
| Job Name | Unique Azion identifier for the type of stream created. Example: Data Stream HTTP, Data Stream WAF |
| Source | Server that generated the log line. Example: edg-fln-ggn001p |
| Status Code | HTTP status code of the request. Example: 200 |
| Streamed Lines | Total amount of lines streamed to the configured endpoint. Maximum value of 2000. This field is the result of a sum. Example: 837 |
| URL | The URL to which the client data was sent/sink. Example for a HTTP POST endpoint: https://log-receiver.azion.com:9200 |
Activity History
Activity History carries one record per action performed on an Azion account, as Activity History registers it. The record names who performed the action, the resource it changed, and the payload the request carried.
Activity History records are kept for 2 years, a longer window than every other data source holds. The Real-Time Events GraphQL API is what reaches the older ones. For the retention of the other seven data sources, refer to Limits.
In the GraphQL API the same records are the activityHistoryEvents dataset, which carries no previous name. For its fields, refer to activityHistoryEvents.
| Variable | Description |
|---|---|
| Account ID | Account’s identifier on Azion. Example: 8437 |
| Author Email | Email address of the Console user who performed the action. Example: myemail@gmail.com |
| Author Name | Name of the Console user who performed the action. Example: Hannah |
| Comment | Editable space available for users to add comments when performing changes. Example: Action performed during investigation |
| Referer Header | Header Referer from the page from which the API was called. Returns when the API call is made from an UI. Example: Test 123 |
| Remote Port | Port of the origin that generated the request. Example: 80 |
| Resource ID | Unique identifier of the resource that was created or modified. Example: 8190 |
| Resource Type | Identifier of the resource that was created or modified. Example: edge_application |
| Request Data | Data received on the payload of the request generated by the user. Example: {"test": 123} |
| Title | Title of the activity, composed of: model name, name, and type of activity. Example: Pathorigin Default Origin was changed |
| Type | Type of performed action on Azion Console: CREATED, CHANGED, DELETED, or SIGNED UP |
| User Agent | Header User-Agent sent in the request. Example: curl 1.2.6 |
| User ID | Unique identifier of the user that executed the action. Example: 999 |
| User IP | IP address of the user/origin that generated the request. Example: 127.0.0.1 |
Time filter
The time filter bounds the period a search covers. It applies on top of the data source: the data source decides which records are read, and the time filter decides how far back the search reaches. Every search runs with one, and the filter opens on the last 15 minutes until another period is picked.
The classic view offers eleven periods:
| Period |
|---|
| Last 15 minutes |
| Last 1 hour |
| Last 3 hours |
| Last 6 hours |
| Last 12 hours |
| Last day |
| Last 2 days |
| Last 3 days |
| Last 5 days |
| Last 7 days |
| Custom time range |
A custom range selects a date and time range inside the last 168 hours. The retention window is therefore the outer bound of what a search can ask for. Activity History is the exception, because its records are kept for 2 years. For the retention values and the bounds a query carries, refer to Limits.
Datasets with no Console data source
Four datasets in the Real-Time Events GraphQL API have no data source in Azion Console. Two of them carry Azion Mobile SDK telemetry and are reached through the API alone: telemetryDeviceInfoEvents holds the device records, and telemetrySensorsEvents holds the sensor records.
The other two are deprecated and are replaced by datasets this page already documents. l2CacheEvents is replaced by tieredCacheEvents, and idnsQueriesEvents is replaced by edgeDnsQueriesEvents. Write a new query against the replacement rather than the deprecated name. For the fields of all four, refer to Real-Time Events GraphQL API fields.